PT-2024-7227 · Foxmarks · Foxmarks

Zefr0X

·

Published

2024-10-04

·

Updated

2024-10-15

·

CVE-2024-47884

CVSS v2.0

4.6

Medium

VectorAV:L/AC:L/Au:S/C:C/I:N/A:N
Name of the Vulnerable Software and Affected Versions foxmarks versions prior to 2.1.0
Description The issue is related to the creation of a temporary file in the /tmp directory with insecure permissions, allowing a malicious user to read confidential information from Firefox's database, including bookmarks, history, and input history. This occurs when the targeted user executes foxmarks bookmarks or foxmarks history commands.
Recommendations For versions prior to 2.1.0, update to version 2.1.0 to resolve the issue. As a temporary workaround, consider restricting access to the /tmp directory or monitoring the directory for insecure temporary files created by foxmarks.

Exploit

Fix

Weakness Enumeration

Related Identifiers

BDU:2024-08568
CVE-2024-47884
GHSA-8RH2-6PWM-5VVQ

Affected Products

Foxmarks